URLhaus Database

You are currently viewing the URLhaus database entry for https://hatti.us/otn/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2659362
URL: https://hatti.us/otn/
URL Status:Offline
Host: hatti.us
Date added:2023-06-13 17:52:17 UTC
Last online:2023-06-15 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-13 17:53:39 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:1 day, 22 hours, 51 minutes Poor (down since 2023-06-15 16:45:28 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-15document_BF094_Jun_15.zipzip db93500e44a2684e71d044699c1c5270916723e212ccdb4957d1eacfb41864a8Virustotal results 6.45% Quakbot
2023-06-15document_BF637_Jun_15.zipzip 397af3d2a51bf2f40bfbca016de11b6387af37aaa80babbca30568274fcb01c0Virustotal results 6.67% 
2023-06-15document_CE617_Jun_15.zipzip 9e020cf4f0bd23ab9a48f9e4101b8a570ed72c4190fd1a0401f13b171b3a2fean/a Quakbot
2023-06-15uui4NvKOXGIGOw.jsjs c6d768419a9ef82beb573581bbb7ee45574cafd8e1c58eee4ee0cc6756d28011n/a 
2023-06-15JnX3F0jgNnpdN.jsjs 3face16d6d4dd243c8763bc1da11ec9f1fe69d283bde2872086918d68b8ec028Virustotal results 15.25% Quakbot
2023-06-15iU2TZyJjvkikO.jsjs ee0f2588c4e28c9dcdaf065bedd3a273757fc68b420fda05ea5176162aa8e63fn/a Quakbot
2023-06-15QDG0Ene2Tpuga.jsjs 9ae2325a697b0cfa262d5dd6914179963f1fd62278957352dd69d24b452f6959n/a Quakbot
2023-06-15V4t6va6E55V1.jsjs 3eaa5cd35f23e1c252e24c6fe93707e013aea831a8f7d1b93456a5da9f0c08d8Virustotal results 0.00% Quakbot
2023-06-14SrMckJ2QpCvm.jsjs 6f9ab119ea99c485556404092e59d8b25555637d88ae7b38bf2a227a63ea803cVirustotal results 0.00% Quakbot
2023-06-144XvL0Ans1PFX8.jsjs f3a36b2caa32b9732ece59b93d2d2e8d39a4548c271c324e46f5c6560159f4d6n/a Quakbot
2023-06-14ksDH5IES1rCo.jsjs a7f7edc57c3f19dffd1f41fad344e40e3428eada07d14a7aa6408314781cff7en/a Quakbot
2023-06-14Y7U0NQroXSikb.jsjs b9ffb402836bd3d588877a6c08f403f6668733547cd631d175d9ff91e19e5516Virustotal results 0.00%Quakbot
2023-06-14j9vV4hXPweiQwz.jsjs d388ac13232edae5a470d05c1344730f7dea4ecdae32a62247c4aef2caea76e0Virustotal results 0.00% Quakbot
2023-06-14vASIJDHN0xbS.jsjs 6e68ba473d14899006b97362c0d8ceb9c8443e93b7ed48bec6fc1ad0f3302448Virustotal results 0.00% Quakbot
2023-06-14b5LtrJFTn04eU.jsjs 55c8be1e1a0c0810b4f4802ded6ef7c533d8b03d5e13fadb81d2a7e7a1ace963Virustotal results 0.00% Quakbot
2023-06-14bK1tUo6KZFoz6P.jsjs 9efdf759a7bfbb48310e66c322b48ff213edac8fbccfa22e67e736ceaa0a79ddVirustotal results 1.69%Quakbot
2023-06-14AFJ5ZiVbTl8R4.jsjs b0c70e0ff93c798e12fda4250c14f7b6ba871df13eb40e2edebf33d32f5a0187Virustotal results 0.00% 
2023-06-14kZLSuk2SwLAyi.jsjs 5753f55c05a68b834cdff1ebfd4d028b671668cecc8be172dfa396148308a296Virustotal results 0.00%Quakbot
2023-06-14Ny2FasaLCKN3d.jsjs e24dae59a010130abde32f4eaff31e39090feeea4c7c45ae39cf343fccb72881Virustotal results 1.69%Quakbot
2023-06-14f96FThhlL9LZ6Y.jsjs 8078300995793eb83fe4dba91216d419413da4492e3ad128102d9ee32b28c8b8n/a Quakbot
2023-06-14GWMJr93Eh7uz.jsjs 7984a42038e2a43c962e3905e58600961abff637e8edb01191371cc1e4eb70bcVirustotal results 15.25% Quakbot
2023-06-14Vumyj84I5g7Ui.jsjs ba6ae33aac46c547117046524d4642fde6b2bad02224fdd96966517b808ffd87Virustotal results 0.00%Quakbot
2023-06-14VW2EYAO9FPBO0r.jsjs 53c1fa6e950d5688bb7ecd26f397579a37fcfb28d12869a0b7f7c4899a9d6cc8Virustotal results 0.00%Quakbot
2023-06-13ja91Jyk1AdtMKs.jsjs 33cd588c4ebfa4a6ba76143306d7e61cda9250ddba43c215bd05c71dcbe42e3dVirustotal results 15.25% Quakbot
2023-06-13uqcQj3FzRwMW.jsjs 4361924f83937cbc2c909d1cff503b72eda3e2574e3382e00be549fe31f5295bn/a Quakbot
2023-06-13O4kzGjp5130Fp.jsjs 325e486140498c768d75e86b2139832ae5fb99960c3a5e5ab1aef3940146850an/aQuakbot
2023-06-1317qKnHsCgvWh.jsjs 3052e8ce4ca4a564e8154728bbc1b20f272d4299d9b6e22b26019ac84c540f96Virustotal results 15.25% Quakbot
2023-06-13FqDIMAWYgKbB.jsjs 0662f2e0e377b02e676e6a5a82ab0992d5aa2dcf46a99213872c8370333b8f0bn/a Quakbot